Cybersecurity checklist for small businesses

The people behind cyber attacks and data breaches don’t care what size business you are; all they care about is the information you have, and how they can make money out of poorly protected data.

The good news is that improving your cybersecurity does not have to be complicated. With the right support, a clear process, and a small business cybersecurity checklist, you can reduce risk, protect your data, and keep your business running smoothly. 

Importance of cybersecurity for small businesses in the UK

Small businesses are regularly targeted because criminals know they may not have the same level of information security, protection, training, or monitoring in place compared to big corporations and businesses. 

In a recent survey, just over 4 in 10 UK businesses reported a cyber security breach or attack in the previous 12 months. This means that cybersecurity isn’t a “nice-to-have” option; it’s an important part of your business, protecting your data, your customers, and your business.

To learn more about information security, view our blog on “What is information security?

Common threats small businesses face 

Small businesses face a wide range of cyber threats, but some are far more common than others.

Common cybersecurity threatsWhat it meansWhy it matters
Phishing emailsFake emails designed to trick someone into clicking a link, sharing a password, or transferring money. They often look like they come from a supplier, bank, delivery company, or even a colleague.Phishing is one of the biggest risks for small businesses because it can lead to stolen data, financial loss, or unauthorised access to business systems.
Weak passwordsSimple passwords, reused passwords, or accounts without multi-factor authentication can make it easier for criminals to access systems.Weak password security can leave email accounts, cloud platforms, and business files exposed.
RansomwareA type of malware that locks files or systems until a payment is demanded.Ransomware can stop a business from accessing important data and cause serious downtime.
Unpatched softwareSoftware that has not been updated, including laptops, servers, apps, plugins, or cloud systems.Criminals can exploit known weaknesses in outdated software to gain access to systems.
Poor user access controlStaff having access to more systems or files than they need, old user accounts, shared logins, or unnecessary admin permissions.Poor access control increases the chance of a breach and can make it harder to limit damage if an account is compromised.
Unsecured cloud servicesCloud platforms such as Microsoft 365, cloud storage, and online systems that have not been configured securely.Poorly secured cloud services can leave sensitive business data exposed.

Cybersecurity checklist for small businesses

Use this free cybersecurity checklist as a starting point for reviewing your business cybersecurity protection plan.

1: Use strong passwords

As simple as this can be, we still have people and businesses that have their main password as “their name 123″, their pet names, date of births, and kids’ names.

Passwords are supposed to be easily remembered, but not easily guessed. We suggest creating stronger and more unique passwords by having numbers and punctuation mixed in, whilst not repeating passwords throughout every site or account you own. 

2: Multi-factor authentication

Multi-factor authentication, also known as MFA or 2FA, adds an extra layer of protection to your accounts. Even if your password has been guessed or stolen, the criminal behind the screen will still need some form of verification to access your account. 

2FA is a type of network security protection that should be used on all of your key systems, like your emails, banking, cloud storage (if you use it), and your Microsoft and Google accounts.

3: Keep updated

Most updates on your phone and computer involve security fixes. Annoying as they are, software updates are incredibly important to your business, data, and your personal systems. A short 5 or 10-minute update time is nothing compared to the time having to reset passwords, pause banking, and letting customers know their data has been compromised. 

4: Data backup

Data backups are vital for small businesses. If you are unlucky enough to be targeted by ransomware, you can always have a backup of your data.  Backups are normally automatic and secure, depending on your provider, like Google etc. 

5: Training

You and your staff are one of your strongest lines of defence. Simple training can help them spot phishing emails, suspicious links, unusual payment requests, and unsafe attachments.
GOV.UK recommends free cyber security training for businesses and staff, including practical online learning from the NCSC!

6: Secure your email

Email is one of the most common ways cyber criminals target businesses. Make sure your email accounts are protected with MFA, spam filtering, and anti-phishing tools.

7: Review who has access

Check who has access to your systems, files, email accounts, and admin tools. Remove old users, especially when employees leave.
Staff should only have access to what they need to do their job. Admin access should be limited and carefully controlled.

8: Protect your devices

All business devices should have suitable security protection in place. This includes antivirus or endpoint protection, device encryption, screen locks, and remote wipe options where appropriate. This is especially important if your team works remotely or uses laptops outside the office.

9: Create a cyber incident plan

Every small business should know what to do if something goes wrong.

Your plan should cover who to contact, how to isolate affected devices, how to restore backups, how to communicate with customers, and how to report the incident.
The NCSC provides small business guidance on response and recovery to help organisations prepare for and recover from cyber incidents.

10: Work towards Cyber Essentials

Cyber Essentials is a UK-backed scheme designed to help organisations protect themselves against common online threats. It focuses on five key technical controls, including secure configuration, user access control, malware protection, security updates, and firewalls.

Cybersecurity plans for small businesses

Cybersecurity is not about making your business impossible to attack; it’s about putting the right layers of protection in place, reducing risk, and knowing what to do when something happens.

At Bigtek, we help small businesses around the UK understand what they are vulnerable to and what needs to be improved. From Microsoft 365 services, access to backups and protection, to cyber security advice, we can help you create a clear and effective plan that fits into your business right away.

Need our help? Contact us today, and we’ll help you build a practical cybersecurity plan for your small business. 

Related blogs

Please select listing to show.
Please select listing to show.
Please select listing to show.
Call Us